SCS-C02 Infrastructure Security Practice Question
A security engineer is configuring a security group for a web server that should only accept HTTPS traffic from the internet. Which inbound rule should be set?
⚠ Common exam trap
SCS-C02 often tests port-number recall under time pressure — candidates confuse 443 (HTTPS) with 80 (HTTP) or pick 22/3389 thinking 'secure' means SSH/RDP, when the question specifically asks for HTTPS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP port 443 from 0.0.0.0/0
HTTPS uses TCP port 443, so an inbound security group rule allowing TCP 443 from 0.0.0.0/0 permits HTTPS traffic from any internet source. This is the standard configuration for a public web server that must accept secure web traffic. Security groups are stateful, so return traffic is automatically allowed without an outbound rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP port 3389 from 0.0.0.0/0
Why it's wrong here
Port 3389 is RDP (Remote Desktop Protocol), used for interactive administration of Windows instances, not for serving web traffic. Opening it to 0.0.0.0/0 exposes the instance's administrative console to the entire internet, inviting brute-force login attacks and potential compromise. A web server security group should omit this rule; if remote administration is needed, restrict RDP to a specific management CIDR or use AWS Systems Manager Session Manager.
- ✗
TCP port 22 from 0.0.0.0/0
Why it's wrong here
Port 22 is SSH, the administrative remote shell protocol for Linux/Unix instances, and it does not carry HTTPS web traffic. Allowing 0.0.0.0/0 on SSH makes the instance targetable by automated credential-stuffing and key-discovery attacks across the public internet. SSH access should be limited to internal admin ranges or placed behind a bastion host, while web traffic should only enter through port 443.
- ✗
TCP port 80 from 0.0.0.0/0
Why it's wrong here
Port 80 is HTTP, not HTTPS, so a rule permitting it from all sources does not satisfy the requirement to expose a secure web endpoint. Plaintext HTTP traffic is subject to eavesdropping and tampering because there is no TLS encryption, and unless the web server or load balancer performs a redirect to HTTPS, clients would connect without confidentiality. For a web server intended to serve HTTPS, the security group should allow inbound TCP 443 rather than relying on port 80.
- ✓
TCP port 443 from 0.0.0.0/0
Why this is correct
Port 443 is HTTPS, the default port for encrypted web traffic using TLS. Because the instance is intended to serve a public website, allowing inbound TCP 443 from 0.0.0.0/0 lets internet clients reach the service securely while security groups remain stateful, automatically permitting return traffic. This rule aligns with the stated requirement and is the correct enablement for a web server receiving secure browser connections.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.